PT-2022-6231 · Oracle · Oracle Web Applications Desktop Integrator
L1K3Beef
·
Published
2022-10-18
·
Updated
2026-03-11
·
CVE-2022-21587
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Oracle Web Applications Desktop Integrator versions 12.2.3 through 12.2.11
Description
A flaw exists in the Upload component of Oracle Web Applications Desktop Integrator within Oracle E-Business Suite. This issue allows an unauthenticated attacker with network access via HTTP to compromise the application. Successful exploitation can lead to a complete takeover of Oracle Web Applications Desktop Integrator. The vulnerability is easily exploitable and has been actively exploited in the wild. Analysis indicates that exploitation can be achieved through payloads based on Perl and Java Server Pages (JSP) for remote code execution. Reports suggest this issue was exploited as early as January 2023, with a proof-of-concept (POC) published in February 2023.
Recommendations
Versions 12.2.3 through 12.2.11 should be updated to a newer, secure version.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Oracle Web Applications Desktop Integrator